Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Cursor Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

cursor-agent-2026.09.28-64d2043-docker, cursor-agent-docker

Index digest:

sha256:240a0bc402e7eb99f31ad3887a0ad746584bec0c1376d1837e35688821555871

Manifest digest:

sha256:889ff8bb5e81e5adb89a8a59b82d3ad63cfb2a3812de602bcec32419f3017b5d

Size

630.93 MB

Last pushed

1 day ago

Vulnerabilities

0
4
11
52
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:cursor-agent-2026.09.28-64d2043-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:cursor-agent-2026.09.28-64d2043-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:f79df28e00ca9b8bf57066a2b900b1c6f90775c3a7d88378b750c036c7024803
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:3131fce854346cec8442d9b2b109710d73508e031eddb81ed71fbae5bc57697b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:cd8f0b4ed116eb05fcab84ba5135356fea050d3731a2fcf6cb075da78b994b8f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:db2c4cdd5b1f1959e9c02b2a88b885a03c9a02fb960975fff409cd514a8021e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:90e6b0c181b36a3dc4f2b04ec2ad51d24dfaf93fafd79db35a9c9116b13b3eaa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:992dd4f4dac480e0737223665b871a9b3ff816f1eafc119a79990a404cad83a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:273b39504f10f73a527a9e25e7f7e8ba4b96e4edde32a44ba5950f3287d9dcf0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:9c01a6741d2ba48ed653c2338367fe5b7a9a45b2479e2a66e91824b666b0ddea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:84d5eb3931afe6a95b12b8f53fb8863694d69d89a65f39f45bd154ddbb09c653
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:3888cedbed4ee1baf0832f70ab4d855f370dd93139800d511f498c11d8131988
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:90a8edee937479caeb5f56914ee36abf0a5dc603a69c1eb0bbd1f4dba469c852
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:c88f0d3ae953d4c42fbd916dcc48b9fda78f951d2ae4348bd98a5e8d43ecbf7e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:4b55dda5e9e1f866211d398fc6a010195040a04851ce415382d3893bdf6c9607
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:be4e1f7f1fa7867636bebf12e371c778d582a869b7564807968c692908c86a2b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:6b101850bb7c475a10b5670afce15bb0eeb16b6283a2d0c03e57d22fa52b2acc